腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Attack ] Google 身份验证器的攻击介绍: https://www.unix-ninja.com/p/attacking_google_authenticator
-
[ Browser ] Chrome JSCreateObject 中的类型混淆漏洞和实现 RCE 利用方法的详细介绍: https://blogs.securiteam.com/index.php/archives/3783
-
[ Browser ] MWR Labs 分享赢得 Pwn2Own 2018 Safari 比赛所使用的漏洞与利用方法,whitepaper: https://labs.mwrinfosecurity.com/assets/BlogFiles/apple-safari-pwn2own-vuln-write-up-2018-10-29-final.pdf ; slides: https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-t2-big-game-fuzzing-pwn2own-safari-final.pdf
-
[ Bug Bounty ] Google referer 头信息泄漏漏洞挖掘之旅: https://thesecurityexperts.wordpress.com/2018/10/28/journey-through-google-referer-leakage-bugs/
-
[ Firmware ] 如何使用树莓派制作智能手机: https://stewardsnotes.ca/2018/10/11/building-the-rcrumbl-the-ultimate-raspberrypi-phone-part-1/
-
[ iOS ] iOS DFU 和 iOS Recovery Mode 介绍: https://blog.elcomsoft.com/2018/10/everything-about-ios-dfu-and-recovery-modes/
-
[ Linux ] Kali Linux 2018.4 发布: https://www.kali.org/news/kali-linux-2018-4-release/
-
[ Malware ] 垃圾邮件活动中恶意附件使用的新文件类型一览: https://blog.trendmicro.com/trendlabs-security-intelligence/same-old-yet-brand-new-new-file-types-emerge-in-malware-spam-attachments/
-
[ MalwareAnalysis ] Mac 上的加密货币价格追踪应用 CoinTicker 存在后门: https://blog.malwarebytes.com/threat-analysis/2018/10/mac-cryptocurrency-ticker-app-installs-backdoors/
-
[ MalwareAnalysis ] 针对巴西的 Android 银行木马在 Google Play 上已有超过一万次的安装量: https://lukasstefanko.com/2018/10/android-banking-malware-found-on-google-play-with-over-10000-installs-targets-brazil.html
-
[ Programming ] CertCheck - 在 C++ 和 C# 语言中以编程方式访问 TLS 证书链的例子: https://github.com/malcomvetter/CertCheck
-
[ Tools ] WebMap - Nmap XML 报告的 Web 图表显示工具 : https://github.com/Rev3rseSecurity/WebMap
-
[ Tools ] JQShell - jQuery 文件上传插件漏洞利用工具: https://github.com/gunnerstahl/JQShell
-
[ Linux ] Linux Kernel xfs_attr_shortform_addname 函数拒绝服务漏洞(CVE-2018-18690) : https://tools.cisco.com/security/center/viewAlert.x?alertId=59066
-
[ MalwareAnalysis ] GandCrab 勒索软件分析报告: https://www.gdata.de/fileadmin/web/de/documents/whitepaper/G_Data_WhitePaper_-_Analysis_of_Win32.Trojan-Ransom.GandCrab.R.pdf
-
[ MalwareAnalysis ] 针对俄罗斯银行的 GPlayed 银行木马分析,来自 Cisco Talos: https://blog.talosintelligence.com/2018/10/gplayerbanker.html
-
[ Pentest ] 使用 Meterpreter 中的 SMB 命名管道进行横向渗透: https://medium.com/@petergombos/smb-named-pipe-pivoting-in-meterpreter-462580fd41c5
-
-
[ Virtualization ] 通过攻击性的安全研究来强化 hyper-v,来自 BlueHat v18 议题(Video) : https://www.youtube.com/watch?v=8RCH0vFxWT4
-
[ Vulnerability ] 椭圆曲线数字签名算法(ECDSA)生成签名中的时序攻击漏洞(CVE-2018-0735): https://mta.openssl.org/pipermail/openssl-announce/2018-October/000135.html
-
[ Windows ] 通过 Windows 内核 API 在 Windows 通知工具(WNF)状态名中持久化保存 .NET Payload 的 POC : https://twitter.com/i/web/status/1056443235457855493